Privacy Policy
Last updated: July 22, 2026
IndexHub ("we", "the Service") is an SEO analytics dashboard available at indexhub.pro. At your request it connects to your own analytics and webmaster accounts and shows your own statistics in a single panel. This policy explains what data we process, why, how long we keep it and what rights you have. Short version: we read your data only to show it back to you, we never sell it, and you can delete everything at any time.
1. Data we process
- Account data: your email and name (provided at registration), password hash. We never store passwords in plain text.
- Data from connected services (read-only): with your explicit authorization we read statistics from Google Search Console (clicks, impressions, positions, queries, pages), Google Analytics 4 (sessions, users, pageviews), Yandex.Metrica (visits, users, pageviews, goal completions), Yandex.Webmaster (site quality index, pages in search, site problems) and Bing Webmaster Tools (clicks, impressions). Access is read-only for every provider — the Service cannot modify anything in your accounts.
- Access tokens (OAuth tokens / API keys) — used solely for scheduled synchronization of your data; stored encrypted.
- Project data: the site domains you add, groups, favorites, plus your notes, tags and query labels.
- Public technical data about your domains: WHOIS/RDAP registration dates, SSL and availability status, favicon — collected from public sources to power monitoring warnings.
- Technical logs: standard server logs (IP address, browser user-agent, request time) and integration sync logs — used for security and troubleshooting.
2. Why we process it
- To show you your own statistics: dashboards, charts, history, position tracking, anomaly and search-engine-update highlights, domain expiry warnings.
- To keep the Service running: authentication, synchronization schedules, error detection, notifications.
- To secure the Service: abuse prevention, log analysis.
We do not use your data for advertising, do not build marketing profiles, do not sell or rent data, and do not use the content of your connected-service data to train machine-learning models.
3. Legal bases
- Contract: account data and project data — required to provide the Service you signed up for.
- Consent: data from connected services — you grant it explicitly via OAuth or an API key and can withdraw it at any time by disconnecting the integration.
- Legitimate interest: technical logs and security measures.
4. Google user data (Limited Use)
IndexHub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Full details, including the exact OAuth scopes we request and how to revoke access — on the dedicated Google API Policy page. In short: Google data is used only for user-facing dashboard features, is never transferred to third parties except as necessary to operate the Service or as required by law, is never used for advertising, and is never read by humans except with your consent, for security purposes, or to comply with the law.
5. Yandex and Bing data
The same principles apply to data received from Yandex and Microsoft Bing APIs: read-only scope, display in your dashboard only, no resale, no transfer to third parties, no advertising use.
6. How long we keep data
| Data | Retention |
| Statistics snapshots | While the related project exists in your account — they power chart history. |
| Access tokens / API keys | Until you disconnect the integration or delete the account; revoked and deleted immediately after. |
| Deleted projects | 14 days in the trash (so you can restore), then permanently erased together with their statistics. |
| Account data | Until you delete the account; deletion removes projects, statistics, tokens and notes. |
| Technical logs | For a limited period needed for security and troubleshooting. |
7. How we protect data
- Access tokens and API keys are stored encrypted at rest.
- All traffic between you and the Service, and between the Service and providers, goes over HTTPS/TLS.
- Each user's data is logically isolated — one user can never see another user's projects or statistics.
- Infrastructure access is restricted to the operator; regular backups are kept for disaster recovery.
8. Who we share data with
We do not sell and do not share your data with third parties for their own purposes. Data is processed only by:
- Hosting/infrastructure providers that run our servers — strictly to operate the Service;
- Authorities — only when required by applicable law.
9. Your rights
- Access and export: your statistics are always visible in the panel; query data can be exported to CSV. For a full data export, contact support.
- Disconnect: any integration can be disconnected at any time — we revoke and delete the tokens.
- Delete: you can delete any project or your entire account yourself; associated data is removed as described in section 6.
- Withdraw consent on the provider side: Google — myaccount.google.com/permissions; Yandex — account access settings; Bing — regenerate/delete the API key.
- Requests: we answer privacy requests within 30 days.
10. Cookies and site analytics
We use essential cookies (session, CSRF protection) and — only with your consent, given in the cookie banner — analytics cookies (Google Analytics 4, Yandex.Metrica) to understand how the site is used. Analytics can be declined or switched off at any time; site analytics data is aggregate and separate from the statistics of your connected accounts. Details, exact names and lifetimes — on the Cookies page. No advertising cookies.
11. Children
The Service is not directed at children and is intended for users aged 16 and over.
12. Changes
We may update this policy as the Service evolves. The current version always lives on this page with the date above; for material changes we will notify you in the Service.
13. Contact
Privacy questions and requests: support@indexhub.pro.